CVE-2026-27751
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to gain full administrative control of the device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.45%
- CWE
- CWE-1392
- Published
- 2026-02-27
- Last modified
- 2026-03-12
Affected products
- Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks) SODOLA SL902-SWTGW124AS
Weakness type
Related vulnerabilities
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-76155 — Datiphy Data Management Center - Use of Default Credentials
- CVE-2026-65313 — Use of hard-coded VNC credentials in the engineering-workstation provisioning
- CVE-2026-68503 — LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard
- CVE-2026-41939 — Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
- CVE-2026-44761 — Insecure Sample Credentials in SAP Commerce Cloud
- CVE-2026-3144 — IBM API Connect Default Credentials
- CVE-2026-58466 — AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()